Breaking Changes
Doc updateThe breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.
Daily.Entra.NewsMicrosoft Entra will move its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft worldwide in late November 2026. Global Secure Access release notes also set out automatic Windows Update upgrades for eligible clients beginning in November, while new App Gallery guidance and revised administration documentation clarify publishing, group creation, and tenant-creation requirements.
Microsoft Entra is updating the self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft and consolidating related sites. The worldwide rollout is planned for late November 2026; users need no action, but administrators should allow *.cloud.microsoft in network policies.
Starting in November 2026, eligible Windows clients will receive Global Secure Access upgrades through Windows Update. Version 2.32.294 adds Prefer local network, faster tunnel creation, and other fixes and improvements. Administrators opting out must use the documented installer parameter and maintain updates manually.
A new tutorial documents the self-service publishing workflow: complete validation prerequisites, create a submission, select capabilities, provide required application details, submit for Microsoft review, and track drafts. The guidance is primarily relevant to administrators supporting application publishers.
The Create Tenant guidance now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting. Accounts expected to create add-on tenants therefore need that role.
The Groups Settings V2 guidance now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed from the documentation.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.
The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.
The new page lists SCIM API, authentication, testing, support, documentation, customer deployment, and cloud compliance requirements for publishing user provisioning integrations in Microsoft Entra App Gallery.
A tutorial now explains how to use the Microsoft Entra App Validator browser extension with non-gallery enterprise applications, including IdP- and SP-initiated SSO, certificate scenarios, optional Single Logout, and result submission.
The documentation explains how to use the Microsoft Entra App Validator browser extension to test an OIDC multitenant app, review fixes, and generate the Test ID required for gallery publishing.
Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.
The guide title now uses quoted punctuation, and the table separator spacing was standardized.
The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.
The page title changed from “What is single sign-on (SSO) in Microsoft Entra ID?” to “What is single sign-on in Microsoft Entra ID?”
The documentation explains how to access the Microsoft Application Network portal and submit requests to update SSO, MDM, or user provisioning details, upgrade SSO, or remove an application listing.
The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.
The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.
The permission-addition and permission-removal examples now use different sample object and client IDs.
The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.
The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.
A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.
The page title now says “Microsoft Entra ID,” and several table separators were reformatted for consistent Markdown presentation.
The documentation now explains that Agent ID objects are covered through their underlying directory object types, including user accounts as user objects and identity blueprints as application objects.
Removed an extra space from the Help desk admin row in the documentation table.
Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.
The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.
The recovery model documentation now lists agent user accounts, agent identity blueprints, agent identities, and agent identity blueprint principals among covered objects.
The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.
The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.
Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.
The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.
The documentation received a minor formatting change with no substantive content changes identified.
The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.